This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP Video Game Security Framework"
From OWASP
(→Governance & Compliance) |
(Updated Governance & Compliance (1st draft)) |
||
Line 325: | Line 325: | ||
'''Governance & Compliance Process''' | '''Governance & Compliance Process''' | ||
<br /> | <br /> | ||
− | :1. Regulation | + | :1. Regulation Alignment |
− | :2. Audit | + | :2. Audit Process |
− | :3. Monitor | + | :3. Monitor Method |
− | :4. Control | + | :4. Control Setup |
<br /> | <br /> | ||
− | '''1. Regulation''' | + | '''1. Regulation Alignment''' |
<br /> | <br /> | ||
Line 371: | Line 371: | ||
<br /> | <br /> | ||
− | 2. ''' | + | 2. '''Audit Process''' |
<br /> | <br /> | ||
Line 422: | Line 422: | ||
<br /> | <br /> | ||
'''''What''''' compliance items do we need to monitor? (prioritize) | '''''What''''' compliance items do we need to monitor? (prioritize) | ||
+ | ''Assess monitoring capabilities available'' | ||
+ | :1) Infrastructure | ||
+ | ::a) Are the technology resources IT environment (Virtual Machines,Applications, Databases, etc.) staying compliant after setup? | ||
− | : | + | ::2)User Activity |
+ | ::a) Are users still able to operate daily job functions with compliance in place? | ||
− | ::a) | + | :2) Processes |
+ | ::a) Is the Disaster Recover plan being implemented and tracked at each stage | ||
+ | ::b) Is the Incident Response plan being implemented and tracked at each stage | ||
− | : | + | :3) Reports |
+ | '''''What''''' monitoring method are we planning to use? | ||
+ | :1) Reports | ||
+ | :2) Dashboards/Charts | ||
+ | :3) Alerts | ||
+ | |||
+ | '''''What''''' monitoring technology can help us achieve this? | ||
+ | :3) Data Analytic tools | ||
<br /> | <br /> | ||
Line 436: | Line 449: | ||
'''''How''''' do we decide on compliance improvement initiatives when a trend appears? | '''''How''''' do we decide on compliance improvement initiatives when a trend appears? | ||
− | :1) | + | :1) Frequency |
− | |||
− | |||
− | |||
− | |||
+ | :2) Complexity | ||
<br /> | <br /> | ||
− | '''4. | + | '''4. Control Setup''' |
<br /> | <br /> | ||
− | During this phase an org must | + | During this phase an org must implement controls in place to ensure as much compliance. The goal should not only be to set up a compliance framework but to use as much automation as possibly. This will in turn reduce overhead and will make compliance easier to manage and modify in the future. |
<br /> | <br /> | ||
Line 453: | Line 463: | ||
<br /> | <br /> | ||
− | '''''How''''' do we achieve | + | '''''How''''' do we achieve compliance standards that are mandatory? |
:1) People | :1) People | ||
Line 461: | Line 471: | ||
:3) Technology | :3) Technology | ||
<br /> | <br /> | ||
− | '''''What''''' can be done to | + | '''''What''''' can be done to automate future compliance controls? |
+ | |||
+ | :1) Automation Code/Scripts | ||
− | : | + | :2) Role-based Security |
− | |||
<br/> | <br/> | ||
{{Social Media Links}} | {{Social Media Links}} |
Revision as of 01:25, 1 May 2019